CVE-2020-24223
MEDIUM NUCLEIMara CMS 7.5 - Cross-Site Scripting via contact.php theme or pagetheme Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-24223. PoCs published by George Tsimpidas. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a Reflected Cross-Site Scripting (XSS) vulnerability in Mara CMS 7.5 via the 'theme' parameter in contact.php. The payload is injected directly into the URL, executing arbitrary JavaScript in the victim's browser.
Description
Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
Exploits (1)
This exploit demonstrates a Reflected Cross-Site Scripting (XSS) vulnerability in Mara CMS 7.5 via the 'theme' parameter in contact.php. The payload is injected directly into the URL, executing arbitrary JavaScript in the victim's browser.
Nuclei Templates (1)
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N